T1219 Remote Access Tools
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Antivirus - Exploitation Framework Signaturecriticalstable · antivirus
- HackTool - Inveigh Execution Artefactscriticaltest · windows
- Antivirus - APT Malware Signaturecriticalexperimental · antivirus
- Antivirus - Remote Access Tools Signaturecriticalexperimental · antivirus
- Atera Agent Installationhightest · windows
- HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicatorshightest · windows
- Hijack Legit RDP Session to Move Laterallyhightest · windows
- Potential CSharp Streamer RAT Loading .NET Executable Imagehightest · windows
- Potential SocGholish Second Stage C2 DNS Queryhightest · windows
- Remote Access Tool - AnyDesk Silent Installationhightest · windows
- Remote Access Tool - Anydesk Execution From Suspicious Folderhightest · windows
- Renamed Visual Studio Code Tunnel Executionhightest · windows
- Suspicious Binary Writes Via AnyDeskhightest · windows
- Suspicious Mstsc.EXE Execution With Local RDP Filehightest · windows
- Suspicious TSCON Start as SYSTEMhightest · windows
- Remote Access Tool - Renamed MeshAgent Execution - MacOShighexperimental · macos
- Remote Access Tool - Renamed MeshAgent Execution - Windowshighexperimental · windows
- Suspicious Velociraptor Child Processhighexperimental · windows
- Anydesk Temporary Artefactmediumtest · windows
- DNS Query To AzureWebsites.NET By Non-Browser Processmediumtest · windows
- DNS Query To Remote Access Software Domain From Non-Browser Appmediumtest · windows
- GoToAssist Temporary Installation Artefactmediumtest · windows
- Installation of TeamViewer Desktopmediumtest · windows
- Mesh Agent Service Installationmediumtest · windows
- Potential Amazon SSM Agent Hijackingmediumtest · windows
Mostrando 25 de 46.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.